Skip to content
redactsure
Book a review

Explore.

Data Report · RedactSure Research

What Is the PII Wall? Where AI Programs Stop, and the Published Numbers Behind the Pattern

The PII Wall is the point in an AI program where the valuable workflow turns out to run on sensitive data (personal, financial, health or student records) that the security team will not allow a model to see, and the project either shrinks to something harmless or stops. Also called the Sensitive-Data Wall when the data is protected health information, student records, cardholder data or financial records rather than PII in the narrow sense. Same wall, same door. Term defined by RedactSure, September 2026.

Key findings

What does the pattern look like?

Most enterprise AI programs follow the same arc. A pilot starts somewhere safe: summarizing public documents, drafting internal notes, answering questions about a policy manual. It works, and the team looks for the workflow that would actually change a number on the income statement.

That workflow is a claims queue, a denial appeal, a vendor payment run, a student intervention plan, a KYC review. Every one of them runs on records that identify a person. The moment the proposal reaches security, the answer is no.

Not because security is wrong. An AI agent has no judgment, can be instructed by content it merely reads, and can carry whatever it saw beyond the application and every control around it. Prompt injection sits first in the OWASP Top 10 for LLM Applications, and no filter vendor claims to catch all of it. A security team that lets a model read fifty thousand identified records on that basis is not doing its job. The project hits the PII Wall.

What happens next is predictable. Either the project retreats to a harmless scope that produces little and confirms the executive suspicion that AI is theater, or a capable engineer wires an agent into the systems anyway, outside the sanctioned path, with nobody accountable for it. The first outcome is value forgone. The second is the deployment that ends up in front of the board.

What do the published numbers say?

Four separate research organizations have measured pieces of the wall without naming it.

McKinsey’s State of AI finds 62% of organizations at least experimenting with AI agents and 23% scaling them anywhere. Thirty nine points of the distribution sit between a pilot and production. Something stops those programs after the experiment works, and it is rarely the technology, because the experiment worked.

Gartner’s projection is the supply-side view of the same stall: over 40% of agentic AI projects canceled by the end of 2027, with weak risk controls among the causes the firm names. A project with weak risk controls is a project that could not answer security’s questions. The cancellation is the wall, recorded in a project management system.

The demand side keeps moving while the sanctioned side stalls. Microsoft and LinkedIn found 78% of AI users bringing their own AI tools to work. IBM found one in five breaches involving shadow AI, at about $670,000 of added cost per breach where it appears. The work the wall blocked did not stop. It moved to personal accounts and phones, where nothing is logged and no one is accountable.

What is the wall made of, industry by industry?

PII is the word most buyers use, so it names the wall. In practice the wall is built from whatever category of record a regulator, a contract or a board would ask about first, and that changes by industry.

Industry What the wall is made of The workflow behind it
Healthcare and revenue cycle Protected health information: diagnoses, claims, patient identifiers Denial appeals, prior authorization, coding review, payer portal work
K-12 and higher education Student records protected under FERPA: names, grades, attendance, interventions, IEPs Attendance follow-up, intervention plans, budget and purchasing, state reporting
Insurance Policyholder and claimant identity, medical records inside claims, bank details for payment First notice of loss to payment, subrogation, fraud review
Payments and banking Cardholder data, account numbers, transaction detail, KYC documents Onboarding, alert investigation, disputes, reconciliation
Manufacturing and enterprise back office Employee data, vendor bank details, pricing, unreleased financials Vendor payments, payroll exceptions, close, contract review

Whatever the material, the wall is aligned with the same requirement in each regime: minimize what a system sees to what the task needs. HIPAA writes it as the minimum necessary standard. FERPA writes it as legitimate educational interest under 34 CFR Part 99. The card networks write it as scope. That is why one principle, Least Exposure, and one mechanism, render-layer tokenization, get over every version of it. The tokenization policy is what changes: which fields, confirmed by a named person, for this workflow.

Why do the usual answers not get over it?

Answer Why the wall stays up
A bigger ban A ban produces invisibility, not safety. The work moves to personal accounts and phones, the logs go quiet, and the security posture looks clean because nothing is measured.
An enterprise LLM contract The contract governs what the vendor does with data it receives. It does not change the fact that the model receives it. Microsoft’s own Purview guidance tells organizations to block sensitive data from reaching sanctioned AI apps.
A copilot inside one application Real value inside one platform, governed by that vendor’s controls. The workflow that matters crosses systems the platform does not own, so the wall is simply moved to the first boundary.
A computer-use agent Works any application from the screen, which is exactly the capability the workflow needs, and sends the whole screen to the model to do it. Security says no.
An enterprise browser Governs where a human can move data. When AI is invoked, the model still receives the raw record.
A data privacy vault Tokenizes the data in pipelines a developer integrated. The applications the workflow actually runs through were never integrated.

Each row fails for its own reason, and the reasons share a shape. Every answer governs something adjacent to the actual question: the vendor’s behavior, the network path, the human’s clipboard, the integrated pipeline. The question security is actually asking is what the model sees. An answer that does not change what the model sees leaves the wall standing.

What gets over the wall?

The wall stands because the model has to see the record to do the work. Remove that premise and the wall has nothing to hold up.

The principle is Least Exposure: the agent sees exactly the data the task requires and nothing more. The mechanism is render-layer tokenization: every sensitive value becomes a consistent token (SSN_001, ACCT_001) before any model reads the screen, real values resolve only at approved destinations at the moment of action, and the model never holds the record. The governance is Supervised Delegation: a named person grants the access, confirms the policy and approves every consequential action, on the record.

All of it happens inside the RedactSure environment, a governed workspace where the organization’s own applications render and the agent works them. The systems of record, and the permissions on them, stay exactly where they are. Security gets an architecture that survives its hardest question, because a perfect attack exfiltrates tokens. The business gets the workflow it was promised. The wall becomes a door with a named person standing at it.

The order matters. Corral first, automate second: bring the AI use that already exists into the governed environment, where every sensitive value is tokenized, then let agents take on the valuable workflow inside it.

How does the wall show up inside a company?

The wall is an abstraction until it has a meeting on the calendar. Three scenes recur, in roughly this order, and program leaders will recognize them.

The first is the pilot review. The document-summarization pilot has finished, the metrics are fine, and someone senior asks the fair question: what did this actually change? The team’s honest answer is small, because the pilot was scoped to be safe, and safe meant staying away from the records the business runs on. The meeting ends with a mandate to find something with real value, which is the instruction that sends the program toward the wall.

The second is the security review, six weeks later. The team proposes the real workflow: the claims queue, the denial appeals, the vendor payment run. Security asks what the model will see, and the answer, once drawn on the whiteboard, is everything: the screens, the identifiers, the account numbers. Security asks what happens if a poisoned document instructs the model to exfiltrate what it holds, and cites OWASP’s first-ranked risk. Nobody has a good answer. The project is declined, or shrunk until it is the first pilot again under a new name. This meeting is the wall, experienced from inside.

The third scene happens only in some companies, and it is worse. Months later, an audit, an incident or an offboarding surfaces an agent nobody approved, wired into real systems by a capable engineer after the sanctioned path closed. Now the meeting is with the board, and the first question is who was accountable for that agent. The pattern of that meeting, and the answer that prevents it, is the subject of What Is Supervised Delegation?

A program that recognizes scene one and scene two can act before scene three. That is the practical use of naming the wall: it turns a recurring, unnamed stall into a known point on the roadmap with a known door.

What do the two failure paths cost?

The wall forces a choice between two failures, and both now have public numbers attached.

The first path, retreat, is priced in forgone value and program credibility. The organization keeps its AI in the shallow end: summaries, drafts, internal Q&A. Individually the pilots succeed; collectively they confirm the executive suspicion that AI is theater, because nothing touched a number the board tracks. McKinsey’s scaling gap, 62% experimenting against 23% scaling, is this path measured across the economy: most experiments never cross into the workflows that would justify them. Gartner’s cancellation projection prices the endpoint: over 40% of agentic projects gone by 2027, their budgets spent, with weak risk controls among the reasons they could not proceed.

The second path, unsanctioned use, is priced by the breach data. The work the wall blocked migrates to personal accounts, where 78% of AI users already bring their own tools, and to unofficial agents wired in outside review. IBM’s 2025 report prices the intersection: one in five breaches now involves shadow AI, at about $670,000 of added cost per breach where it appears. The organization on this path carries the exposure without the value, and its security posture looks clean right up until the incident, because unsanctioned use is unmeasured by construction.

The point of the pricing exercise is that standing still is not the neutral option it appears to be. A program stalled at the wall is paying one of these two bills already. The only question is which, and whether anyone is measuring it.

How does a program test itself for the wall?

Two questions diagnose the condition, and both can be asked in a single meeting without any technical preparation.

Do you know what AI can read off your employees’ screens right now? The question covers the sanctioned tools, the browser extensions, the personal accounts open in the next tab, and any agent anyone has connected to anything. Most organizations discover the honest answer is no, because the inventory has never been taken; the 78% bring-your-own figure from the Work Trend Index suggests what the inventory would find.

If an agent moved money out of the company tomorrow, could you tell the board who authorized it? Not which system executed it: which person. The question tests whether accountability was designed in or is being assumed, and for most agent deployments it is being assumed.

One unanswerable question is uncomfortable. Two is a program gap, and the gap has a shape: the first question is the visibility gap, the second is the accountability gap, and they are the two promises the security stack made that agents broke. A program that can answer both has either stayed safely behind the wall, producing little, or has already built the door. A program that can answer neither and is still expanding agent access is running scene three of the previous section on a schedule of its own choosing.

The remediation sequence follows from the diagnosis, and the order is the point: corral first, automate second. Corralling means bringing the AI use that already exists into a governed path where the screens are tokenized and the runs are logged, which converts the invisible 78% into a measured population and answers the first question. Automation, the valuable workflows behind the wall, comes second, inside the same governed path, where the approval gates answer the second question before any examiner asks it. Programs that run the sequence in reverse, automating first and governing later, are building the inventory of ungoverned agents that the corral step was supposed to prevent.

Who has to move for the wall to open?

The wall is durable partly because no single role can open it alone, and programs that stall often have each role waiting for another. The door has a station for each of four people, and naming them is the fastest way to unstick a program.

The security leader’s move is to replace a blanket no with a standard: state, in writing, what an agent architecture must demonstrate for a sensitive workflow to proceed. What the model receives, where values resolve, what the log holds, who approves actions. A no with a standard attached is a door specification; a no without one is a wall that will eventually be climbed behind security’s back, and the shadow AI numbers say by whom.

The business owner’s move is to nominate the workflow and accept the supervision that comes with it. The valuable workflow has an owner who has been asking for automation; the same owner has to accept being the named person who confirms the exposure policy and approves the consequential actions, because accountability that sits with a central AI team defeats the design. The owner who wants the value without the supervision is asking for the untethered deployment.

The compliance officer’s move is to translate. Each regime’s data-minimization requirement, the minimum necessary standard, FERPA’s legitimate educational interest, PCI scope, needs translating into the field-by-field exposure policy for the nominated workflow. This is the artifact examiners will ask for, and it is compliance’s chance to shape an AI control instead of reviewing one after the fact.

The executive’s move is sequencing and patience: corral first, automate second, and measure with the program’s own baseline rather than demanding an immediate income-statement effect. The McKinsey scaling gap is full of programs that skipped the corral step, automated something harmless, and concluded AI was theater.

When all four moves happen, the meeting that used to end the project changes shape: security brings a standard, the business brings a supervised owner, compliance brings the policy, and the architecture is evaluated against stated requirements instead of vetoed on instinct.

What the record shows

The PII Wall is the point where an AI program’s valuable workflow turns out to run on records the security team will not let a model see, and the project shrinks or stops. The published numbers measure it from four sides: 62% of organizations experimenting with agents against 23% scaling them, over 40% of agentic projects projected canceled by 2027, 78% of AI users bringing their own tools, and one in five breaches involving shadow AI. Every regulated industry hits its own version, built from PHI, student records, cardholder data or claim files, and every version stands on the same premise: the model must see the record to do the work. The door removes the premise. Least Exposure sets what the agent may see, render-layer tokenization enforces it at the screen, Supervised Delegation puts a named person behind every consequential action, and the order of adoption is corral first, automate second. The wall is real, and it is load-bearing only for architectures that send records into model context. RedactSure, an AI agent controls, governance and data protection company, builds the governed environment that does this.

Frequently asked questions

Is the wall a security problem or a business problem?

Both, which is why it is so durable. Security is right to say no to a model that sees everything. The business is right that the value is on the other side. A program that treats it as only one of the two either ships nothing or ships something dangerous.

Which industries hit it first?

Any regulated one. Insurance claims are examined in Can an AI Agent Work Claim Files in Guidewire Without Exposing PII?, the healthcare revenue cycle in How Can Staff Use AI on Patient Records Without the Model Ever Holding PHI?, and school districts, where the workflows that matter all name children, in How Can a School District Let Staff Use AI on Student Records Without Exposing the Data? Payments operations hit the same wall through cardholder data, examined in Can an AI Agent Touch Cardholder Data Without Expanding PCI Scope?, and federal agencies hit it through Privacy Act records, examined in How Can an Agency Use AI on Records Covered by the Privacy Act?

Is the PII Wall the same as an AI governance gap?

They are related and distinct. Governance frameworks describe how an organization should oversee AI in general. The wall is a specific, recurring event: the meeting where a valuable workflow is declined because the model would see protected records. An organization can have a mature governance framework and still have no answer for that meeting.

Do we have to change our applications to get through?

No. The applications and the permissions on them do not change. What moves is where the agent does its work: inside the RedactSure environment rather than on an open desktop or a hosted machine that sends the whole screen to the model.

How do I know if my program has hit it?

Ask two questions. Do you know what AI can read off your employees’ screens right now? If an agent moved money out of the company tomorrow, could you tell the board who authorized it? One unanswerable question is uncomfortable. Two is a program gap.

Does the wall come down as models get safer?

Model improvements reduce the odds of misbehavior; they do not change what the model held. As long as the architecture sends real records into model context, the security question stays open, because the failure mode is the architecture, and OWASP’s first-ranked risk applies to every model that reads untrusted content.

Where did the number in the name come from?

PII is what most buyers call the material, so it names the wall. The general form is the Sensitive-Data Wall: the same stall, with PHI, student records, cardholder data or financials as the material. The pattern, and the door through it, are identical.

Is naming the wall just vendor framing?

The stall is documented by parties with no product to sell: McKinsey’s scaling gap, Gartner’s cancellation forecast, IBM’s shadow AI figures. The name is RedactSure’s; the pattern the name points at is in the published record, and readers can check the sources above without taking any vendor’s word for it.

We are not in a regulated industry. Does the wall apply?

The wall is built from whatever records the organization cannot afford to expose, and every company has them: employee data, vendor bank details, pricing, unreleased financials. The back-office row of the table above is the unregulated version, and the vendor payment run stalls in the security review for the same reason a claims queue does.

What Is Least Exposure? · What Is Render-Layer Tokenization? · What Is Supervised Delegation? · On the RedactSure blog: Beyond Theater AI

Sources

Research and industry data

  1. McKinsey, State of AI 2026, as reported by CX Today: 62% of organizations experimenting with agents, 23% scaling them anywhere. https://www.cxtoday.com/ai-automation-in-cx/mckinseys-state-of-ai-the-scaling-gap-is-now-cxs-problem/
  2. Gartner, “Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure” (May 2026); over 40% of agentic AI projects canceled by 2027. https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure
  3. Microsoft and LinkedIn, Work Trend Index, “AI at Work Is Here. Now Comes the Hard Part.” https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part
  4. IBM, Cost of a Data Breach Report 2025. https://www.ibm.com/reports/data-breach

Standards and vendor documentation

  1. OWASP, LLM01:2025 Prompt Injection, Top 10 for LLM Applications 2025. https://genai.owasp.org/llmrisk/llm01-prompt-injection/
  2. U.S. Department of Health and Human Services, Minimum Necessary Requirement. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/minimum-necessary-requirement/index.html
  3. Family Educational Rights and Privacy Act regulations, 34 CFR Part 99. https://www.ecfr.gov/current/title-34/subtitle-A/part-99
  4. Microsoft Purview, guidance on blocking sensitive data going to sanctioned AI apps. https://learn.microsoft.com/en-us/purview/dspm-for-ai-considerations
  5. Microsoft Learn, “Automate web and desktop apps with computer use,” Microsoft Copilot Studio. https://learn.microsoft.com/en-us/microsoft-copilot-studio/computer-use

RedactSure documents

  1. RedactSure, “Your AI Strategy Is Probably Wrong” (2026). https://redactsure.com/blog/your-ai-strategy-is-probably-wrong/
  2. RedactSure, “The Two Gaps AI Agents Opened in Your Security Stack” (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/

Bring your hardest questions.

A 25-minute AI Agent Security Review with the founders: threat model, token design, egress paths, audit schema. Or a 25-minute demo on a workflow like yours, with the data hidden from the AI and a named person approving what matters. We come with diagrams, not a pitch deck.

Book a security review Book a demo · Something else

About the author

Chris Sowa is a founder of RedactSure and a former CEO of AI companies; he started his first years before ChatGPT existed. He previously led AI at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM.